PodcastsComedySmashing Security

Smashing Security

Graham Cluley
Smashing Security
Neueste Episode

474 Episoden

  • Smashing Security

    AI gets hacked, and BitLocker gets bypassed

    17.06.2026 | 1 Std. 12 Min.
    What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told.
    Meanwhile, someone calling themselves Nightmare Eclipse has decided to teach Microsoft a lesson. The result? Three zero-days dropped on the internet, one of which lets a thief with a USB stick walk straight past BitLocker. Microsoft is furious.
    Plus don't miss our featured interview with Son Nguyen Kim of Proton Pass, who explains why plugging AI agents into your email and calendar without thinking twice is rather like hiring a new employee with the keys to everything - and skipping the background check.
    All this and more in episode 472 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Paul Ducklin.

    EPISODE LINKS:

    ShinyHunters claims 61M Sysco records - Cybernews.
    Derbyshire police officer under investigation for using AI to create evidence - Derbyshire Times.
    Maine forced to take down data breach portal after fake notices filed with authorities - Hot for Security.
    A Fake Bug Report Hijacks Your AI Coding Agent - and Nothing Catches It. - Tenet Security.
    Agentjacking: a fake bug report hijacks AI coding agents - TNW.
    When anti-virus goes rogue - A trifecta of Defender zero-days - SolCyber.
    BitLocker in crisis? The "YellowKey" zero-day in plain English - SolCyber.
    Microsoft versus Full Disclosure: The ongoing Nightmare Eclipse saga - SolCyber.
    BitLocker, Defender, zero-days, and bragging rights: More MS nightmares - SolCyber.
    Inside the FBI’s Kinetic Cyber Range - FBI.
    Inside the FBI's Kinetic Cyber Range - YouTube.
    Computer worm strikes International Space Station - Graham Cluley.
    Raspberry Pi Zero W - Raspberry Pi.
    There’s still life in old technology.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Proton Pass - The password manager for businesses that can't compromise on security or slow their team down. Start a free trial.
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    This AI worm just rewrote its own rules

    10.06.2026 | 46 Min.
    Researchers at the University of Toronto have built a worm that thinks for itself. Using free off-the-shelf AI models it works out how to break into each new computer it encounters, and hijacks the powerful ones to host its own AI brain. And then the researchers discovered their creation had quietly removed the list of machines it wasn't supposed to attack.
    Meanwhile, Meta's shiny new AI customer support agent has been cheerfully helping hackers help themselves to other people's Instagram accounts. Just keep asking, politely but firmly, to have a password reset sent to a different email address - and the AI will eventually agree.
    All this and more in episode 471 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.

    EPISODE LINKS:

    Emmys data leak: update exposes access to award submissions - Cybernews.
    A $1,000 AI agent found 21 zero-days in FFmpeg, some 23 years old - Martin Cid Magazine.
    Hackers steal $1.7M condom shipment​ - Cybernews.
    AI Agents Enable Adaptive Computer Worms - ArXiv.
    21 Zero-Days in FFmpeg - Depthfirst.
    Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot - ~this week in security~.
    Hackers trick Meta AI support bot to infiltrate Obama White House Instagram account - The Guardian.
    Look-In Star Portrait Challenge - Monkeon.
    Final Fantasy VII Remake - Square Enix.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.
    OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    This AI security flaw might be impossible to fix

    03.06.2026 | 57 Min.
    A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to warn the company, it was lawyers who responded.
    Meanwhile, a paper from Cornell suggests that prompt injection - the technique malicious actors use to trick AI agents into doing things they really shouldn't - may be fundamentally unsolvable. Which is err... awkward, because everyone is rushing to plug AI agents into their email, files, and corporate networks.
    Plus don't miss our featured interview with Andrea Sivieri of CoreView, who tells us how hackers can lock your entire organisation out of its Microsoft 365 environment... without having to trick you into running a single piece of malicious code or handing over a password.
    All this and more in episode 470 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Tanya Janca.

    EPISODE LINKS:
    Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked - 404 Media.
    Canon Printer Vulnerability Leaks Plaintext Credentials - Praetorian.
    Password manager Dashlane says hackers stole some customers' password vaults - TechCrunch.
    UK Visa Portal exposed thousands of applicants’ passports and selfies — then called the lawyers on us - TechCrunch.
    AI Agents May Always Fall for Prompt Injections - ArXiv.
    MCP Security Crisis: Systemic Design Flaws in AI Agent Infrastructure - Cloud Security Alliance.
    From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness - ArXiv.
    Design details that feel like magic - Design Spells.
    Singing lessons.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.
    ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    What your Oura ring won't tell you

    27.05.2026 | 53 Min.
    CISA, the US government agency whose entire job is keeping America's critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile.
    Meanwhile, your Oura ring is quietly transmitting some of its data unencrypted - and when one journalist asked the company how often it hands user data to law enforcement, the answer was quite telling.
    Plus don't miss our featured interview with OPSWAT's Benny Czarny about his new book "Cybersecurity Upside Down."
    All this and more in episode 469 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lesley Carhart.

    EPISODE LINKS:

    Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet - US Dept of Justice.
    700+ education and tech websites hijacked in huge ClickFix malware campaign - Malwarebytes.
    Leaked Documents Reveal Russian ‘Cognitive Strikes’ Against the West - Including Islamophobic ‘Pig Head’ Attacks in Paris - OCCRP.
    Lawmakers Demand Answers as CISA Tries to Contain Data Leak - Krebs On Security.
    US cybersecurity agency CISA reportedly in dire shape amid Trump cuts and layoffs - TechCrunch.
    Oura says it gets government demands for user data. Will it share how many? - This Week In Security.
    Privacy and transparency of fitness tracking devices - Whyli.
    Upfest - Europe’s largest street-art festival.
    Magnets Are Bad For Hardware Again - Hackaday.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.
    OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    High-speed train hacks and homicidal lawnmowers

    20.05.2026 | 55 Min.
    A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we've heard all year.
    Meanwhile, owners of $4,000 robot lawnmowers are discovering that their gadget can be hijacked over the internet, redirected at journalists who foolishly lie down in front of it, and used to harvest Wi-Fi passwords, email addresses, and GPS coordinates. Change the default password? Sure - until the next firmware update silently resets it back.
    Plus - don't miss our featured interview with XBOW's Brendan Dolan-Gavitt about how AI is transforming penetration testing.
    All this and more in episode 468 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.

    EPISODE LINKS:

    Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom - TechCrunch.
    Man accused of stealing Beyoncé’s unreleased music takes guilty plea - ABC News.
    Shai-Hulud code drop: Open season for supply chain attacks- ReversingLabs.
    Student hacked Taiwan high-speed rail to trigger emergency brakes - BleepingComputer.
    Polish teen derails tram after hacking train network - The Register.
    The Cheap Radio Hack That Disrupted Poland's Railway System - WIRED.
    The man with an army of Yarbo robot lawn mowers - The Verge.
    Ever been run over by a robot? I have - for science! - TikTok.
    RD280UA 28” WQXGA BenQ Programming Monitor with Backlight and Flexible Arm - BenQ.
    Kai Shun DM-0708 combination sharpening stone, grain 300/1000 - Knives and Tools.
    AI-Assisted ICS Attack on a Water Utility - Dragos.
    Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - Google Cloud Blog.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.
    OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
Weitere Comedy Podcasts
Über Smashing Security
Stories from the world of hacking, cybersecurity, and rogue AI.Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.New episodes released at 7pm EST every Wednesday (midnight UK).
Podcast-Website

Höre Smashing Security, Fest & Flauschig und viele andere Podcasts aus aller Welt mit der radio.de-App

Hol dir die kostenlose radio.de App

  • Sender und Podcasts favorisieren
  • Streamen via Wifi oder Bluetooth
  • Unterstützt Carplay & Android Auto
  • viele weitere App Funktionen
Rechtliches
Social
v8.10.0| © 2007-2026 radio.de GmbH
Generated: 6/18/2026 - 4:11:21 PM